July 2026 Release Notes
The Command Platform release notes include information about what’s new, which are updated monthly, and improvements and fixes, which are updated weekly.
Last updated: July 24, 2026
What’s New
Learn about new features across the Command Platform. These features were released over the past month and are available now:
- Risk: Attack Surface Management (Surface Command), Exposure Command
- Focus remediation efforts with CVE publish date filtering
- Surface Microsoft Defender recommendations in Remediation Hub
- Generate and schedule Top Remediation reports from Remediation Hub
- Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
- Monitor remediation workflow activity in Remediation Hub
- Threat: Digital Risk Protection (Threat Command)
Risk
Risk is the potential for loss or damage to your assets, operations, or reputation, due to vulnerabilities being exploited by a bad actor. Security teams must assess the risk level by evaluating the likelihood of a threat occurring and the impact that it would have if realized.
- Focus remediation efforts with CVE publish date filtering
- Surface Microsoft Defender recommendations in Remediation Hub
- Generate and schedule Top Remediation reports from Remediation Hub
- Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
- Monitor remediation workflow activity in Remediation Hub
Manage Rapid7 Agents (Insight Agents) more efficiently
We’ve updated the Rapid7 Agent Management experience to improve performance, consistency, and reliability. With this release, you can expect:
- A faster, more responsive Agent Management experience.
- More consistent interactions for common tasks, including actions, confirmations, and status messages.
- Improved accuracy and consistency for agent data, metrics, and KPIs.
- Streamlined workflows that make it easier to manage your agent deployment.
These improvements are powered by an updated backend architecture that provides a more reliable foundation for Agent Management today while supporting future enhancements as your environment grows.
Focus remediation efforts with CVE publish date filtering
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes a CVE Publish Date filter, allowing you to view and filter remediations based on when vulnerabilities were publicly disclosed. This helps you identify newly disclosed threats or long-standing vulnerabilities to prioritize remediation efforts effectively.
With this capability from Risk > Remediation Hub, you can:
- Prioritize newly disclosed vulnerabilities using CVE publish date filters.
- Support SLA-driven prioritization and backlog management.
- Target remediation efforts more effectively based on threat timeline.
- Align remediation workflows with organizational priorities and deadlines.
Surface Microsoft Defender recommendations in Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes Microsoft Defender as a third-party remediation source. Customers using the latest Microsoft Defender connector for Attack Surface Management (Surface Command) can view Defender recommendations alongside remediation data from other sources, reducing context switching and helping your team prioritize the highest-impact fixes.
With this capability from Risk > Remediation Hub, you can:
- View Microsoft Defender remediation recommendations directly in Remediation Hub.
- Prioritize Defender findings alongside data from other remediation sources.
- Manage remediation activity in a centralized workflow to reduce context switching.
Generate and schedule Top Remediation reports from Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now includes reporting capabilities based on the Vulnerability Management (InsightVM) Top Remediations report. Generate high-level summary and detailed asset-level reports to prioritize actions, understand impacted assets, and share remediation insights across teams. Reports are available on-demand or on a schedule, in PDF, HTML, and CSV formats.
With this capability from Risk > Remediation Hub, you can:
- Generate summary and asset-level reports on-demand or on a schedule.
- Share reports in PDF, HTML, and CSV formats with security and IT teams.
- Automatically deliver scheduled reports to asset owners to reduce manual follow-up.
- Prioritize remediation across a hybrid environment with data from Vulnerability Management (InsightVM), Cloud Security (InsightCloudSec), and Attack Surface Management.
Access Remediation Hub with Vulnerability Management (InsightVM) role-based permissions
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub is now available to all Vulnerability Management (InsightVM) users — no administrator privileges required. Role-based permissions ensure each user sees only the assets and remediations they are authorized to access, so asset owners can act on prioritized remediations for their assigned assets without relying on security team intervention.
With this capability from Risk > Remediation Hub, you can:
- Access Remediation Hub as any Vulnerability Management (InsightVM) user.
- View only the assets and remediations within your authorized scope.
- See filters and metrics that automatically reflect your assigned asset data.
Monitor remediation workflow activity in Remediation Hub
In Attack Surface Management (Surface Command) and Exposure Command, Remediation Hub now surfaces workflow activity directly, giving security teams visibility into which workflows have run, execution counts, status, and related artifacts such as Jira tickets and ServiceNow incidents — without leaving the remediation workflow.
With this capability from Risk > Remediation Hub, you can:
- View workflow execution history directly in Remediation Hub.
- Monitor execution status, including successful, failed, and in-progress runs.
- Access generated artifacts and workflow outputs in a centralized location.
Threat
A threat is any potential event or action that could exploit vulnerabilities in a system, causing harm to assets, data, or operations. Threats can originate from various sources, including malicious actors, natural disasters, or unintentional human errors.
Control infostealer alert scope with the external user toggle
In Digital Risk Protection (Threat Command), you can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. This gives security teams more control over alert volume without sacrificing visibility into employee credential exposure.
With this capability from Intelligence > DRP Configurations > Customization (or Configurations > Customization in Digital Risk Protection (Threat Command)), you can:
- Toggle external user alerting on or off to refine infostealer alert scope.
- Reduce alert noise by disabling monitoring of external email matches while continuing to monitor internal organizational emails.
- Apply the setting to future alerts only, with no impact on existing or previously resolved alerts.
Updated admin group identification for cloud identity providers
In SIEM (InsightIDR), how cloud admin users are identified has been updated. Admin users from cloud identity providers such as Okta and Entra ID are now determined by membership in a group with a recognized admin role applied, rather than by group name alone. This change improves the accuracy of admin user identification across cloud environments.
Improved AI-powered query generation
We’ve enhanced AI-powered Log Search query generation to better understand natural language prompts and reduce the manual effort required to build searches.
It can now:
- Automatically interpret natural language time expressions, such as “yesterday” or “last 24 hours”, and apply the appropriate time range to the search.
- Suggest relevant log sources and event source types based on the intent of your prompt.
- Provide a more detailed AI Query Explanation that includes the selected time range and log sources, making it easier to understand how your prompt was translated into a search query.
These improvements help you create more accurate searches faster while providing greater transparency into how AI interprets your requests.
Understand your assets faster with AI-generated summaries in Attack Surface Management
The Asset Details view in Attack Surface Management now displays an AI-generated summary of the most relevant information about any asset, so you can quickly get up to speed on what matters most.
Access asset details from Attack Surface Management > Asset Details. With this capability, you can:
- Get an instant overview of the key properties associated with any asset.
- Investigate exposures and alerts with greater efficiency.
- Make faster, more informed prioritization and remediation decisions.
- Maintain a more consistent understanding of an asset across security workflows.
- Provide feedback to the Rapid7 product team using the in-feature feedback option.
Read more about this feature in Explore assets and identities .
Improvements and Fixes
Keep track of improvements and fixes to core technology.
Application Security (InsightAppSec) and AppSpider
No updates released at this time.
Attack Surface Management (Surface Command)
Version 1.0.930
Software release date: July 22, 2026 | Release notes published: July 24, 2026
Improved:
- Vector Command now requires service agreement acknowledgment before initiating testing.
Fixed:
- Asset Correlation Information section now displays unique values without duplication.
- Graphical Query Builder queries using dotted notation for referenced fields now return results consistent with explicit path traversal.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
New Connectors
- Adaptive Security: Adaptive Security is a security awareness training platform that helps organizations protect against phishing and social engineering attacks. This connector imports users and groups from Adaptive Security into Surface Command.
- Avigilon Alta: The Avigilon Alta (formerly Openpath) is a cloud-based physical access control solution for unified video and access control. This connector integrates Users, Access Groups, Access Control Units (ACUs), Readers, and Sites with the Rapid7 Platform.
- Halcyon: Halcyon is an AI-powered anti-ransomware platform that detects, prevents, and recovers from ransomware attacks across managed endpoints. This connector imports Halcyon endpoint assets, tenant organizations, deployment groups, and policy groups into the Rapid7 Platform.
Updated Connectors
- Cloudflare: Zero Trust device collection now ignores accounts where Zero Trust is not enabled, instead of failing the entire import.
- CyberArk Endpoint Privilege Manager:
- Migrated from deprecated GetComputers API to new Get Endpoints API.
- Added
CyberArkEpmComputer2type with full unified model fulfillment.
- Infoblox NIOS DDI: Page size updated to 100 for all functions.
- Microsoft SQL:
- Added a generic import feed with configurable queries.
- Added
mssql_query_configconfiguration type.
- Mosyle MDM: Resolved correlation issue with
MosyleDevicehostname. - SentinelOne Singularity: Strengthened unique key for
SentinelOneSoftwareInstallation. - SonarQube: Fixed null values in SonarQubeIssue and SonarQubeRule
exposure_typefields. - WatchGuard Endpoint Security: Resolved KeyError:
WatchGuardDevicein get_managed_devices by handling pagination state. - Zscaler: Improve correlation on
ZScalerZiaDevice.hostNamevalue.
Version 1.0.929
Software release date: July 15, 2026 | Release notes published: July 16, 2026
Improved:
- Rapid7EASMDomain
resolves_to_refsfield now includes IP addresses and other domains that map to this domain.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
New Connectors
- BlueCat Micetro: BlueCat Micetro is a multi-vendor DDI (DNS, DHCP, and IPAM) management platform that provides a unified interface for managing IP address space and DNS across heterogeneous network environments, supporting Microsoft, BIND, Cisco, Infoblox, and cloud DNS/DHCP services. This connector synchronizes IP address management data and DNS configuration from the Micetro REST API into the Command Platform, including network blocks and subnets, individual IP address allocations with assignment state and discovery metadata, authoritative DNS zones, and DNS resource records.
- Paycom: Paycom is a comprehensive human capital management (HCM) software solution that helps businesses streamline their employment processes from recruitment to retirement. This connector integrates employee data with the Command Platform.
- Scale Computing Fleet Manager: Scale Computing Fleet Manager is a cloud-hosted control plane for hyperconverged edge infrastructure running SC//HyperCore, enabling centralized management of distributed edge systems across multiple sites. This connector imports clusters and virtual machines from Scale Computing Fleet Manager into the Rapid7 Platform, enabling Surface Command to map distributed edge architectures and track the orchestration of edge infrastructure and its workloads.
Updated Connectors
- Armis: Fixed null
exposure_typeonArmisPolicy. - BloodHound Enterprise: Fixed null
exposure_typeonBloodHoundAttackType. - Check Point Harmony Endpoint:
- Updated schema validation for
CheckPointHarmonyEndpointAsset. - Updated dependencies.
- Updated schema validation for
- Crowdstrike Falcon: Fixed invalid and null
exposure_typeonCrowdstrikeVulnerabilityExposure. - GCP Compute:
- Improved guidance when no
GcpProjectIDs are available from GCP Core. - Clarified likely org-level permission dependency (
roles/resourcemanager.organizationViewer).
- Improved guidance when no
- GCP Core:
- Improved
test_connectiondiagnostics when no organizations are returned. - Preserved existing “No organizations found.” logging for no-org environments.
- Added explicit guidance for missing
roles/resourcemanager.organizationViewer.
- Improved
- Google Security Command Center:
- Updated Security Center API to v2.
- Improved error reporting in test connection.
- Infoblox BloxOne Threat Defense: Fixed null
exposure_typeonInfobloxTdSecurityPolicy. - JumpCloud: Fixed
JumpCloudDeviceFQDN hostname correlation. - Microsoft Intune: Separated ingest import feed for devices and software.
- OpenAI: Added OpenAIUsage type for completions usage data.
- PostgreSQL:
- Added generic import feed with configurable queries.
- Added postgresql_query_config configuration type.
- SentinelOne Singularity: Clarified required permissions documentation for Extended Security Posture Management.
- Tenable Security Center: Fixed null
exposure_typeonTenableScPlugin2. - Tenable Vulnerability Management: Fixed null
exposure_typeonTenableIoPlugin2. - Wiz.io: Fixed null
exposure_typeonWizVulnerability. - Zimperium MTD:
- Removed zScan scope.
- Added import feed for CVEs and Threats.
Version 1.0.928
Software release date: July 8, 2026 | Release notes published: July 13, 2026
Improved:
- Connector update failures now include an Update Now button to facilitate immediate resolution.
- The Connectors page now supports reviewing and applying multiple connector updates simultaneously.
- Correlation Rules now display human-readable names and descriptions for automatic exclusion rules to improve clarity and usability.
Fixed:
- Hostname and Domain filters now return matching records consistently across Network Services and Certificates pages.
- The Test Connection button in Connector profile now displays a tooltip and disables when the test function is unavailable, preventing runtime errors.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
New Connectors
- Nutanix Prism Central: Nutanix Prism Central is a centralized multi-cluster management plane that provides a single pane of glass for managing Nutanix infrastructure including virtual machines, hosts, clusters, networks, and images. This connector integrates with the Nutanix Prism Central v4 APIs to import infrastructure asset data into the Rapid7 Platform.
Updated Connectors
- IGEL UMS: Fixed a schema validation error for the IgelUmsDevice type.
- Microsoft Entra ID (formerly Azure AD): Added the
AzureAdAppRoleAssignmenttype; app role assignments are now fetched as part of the applications feed. - SentinelOne Singularity: Added the new
SentinelOneSoftwareInstallationtype, linking per-agent installed software toSentinelOneSoftware.
Version 1.0.926
Software release date: July 2, 2026 | Release notes published: July 6, 2026
Improved:
- Executed queries now display 25 results instead of 10 for better readability.
Connectors
The following connectors were updated in the Extension Library since the previous release. Connector updates are published independently and may have been available before this release date.
Updated Connectors
- BigFix: Fixed a packaging error.
- EZO AssetSonar:
- Fixed schema type mismatches in
EzoAssetSonarMember. - Added previously undeclared API fields to
EzoAssetSonarAsset. - Pinned dependencies.
- Fixed schema type mismatches in
- IGEL UMS: Fixed a schema validation error for
IgelUmsDevice. - Kaseya VSA 10: Added Applied Policies enrichment with the M1051 (Update Software) mitigation.
- Kaseya VSA 9: Added the M1051 (Update Software) mitigation to
KaseyaVSA9Agentusing the patch scan status API. - ManageEngine ServiceDesk Plus: Added schema validation for the
ManageEngineServiceDeskUsertype. - Matrix42 CMDB: Added Asset filter to only import assets with an operational status of Active.
- Nozomi Vantage:
- Added Nozomi certification headers (
nn-appandnn-app-version) to all requests. - Added retry handling for API throttling responses (HTTP 429 and HTTP 503).
- Improved vulnerability pagination and deduplication handling.
- Added Nozomi certification headers (
- SolarWinds IT Asset Management: Fixed hostname correlation.
Cloud Security (InsightCloudSec)
Release availability for self-hosted users
Self-hosted users are able to download the latest version usually 4 business days after SaaS users are upgraded from the following locations:
- Terraform deployments: Public S3 bucket . Modules can be updated with the
terraform get -updatecommand. - Amazon Elastic Container Repository (ECR) deployments: You can obtain the ECR build images for this version from the InsightCloudSec ECR Gallery
Version 26.7.21
Software release date: July 22, 2026 | Release notes published: July 22, 2026
New Features
- Runtime Sensor Health Monitoring: Added real-time health status visibility for runtime sensors across Kubernetes clusters and container instances. The Kubernetes Clusters page and Resources Listing now display a Runtime Sensor status column (Healthy, Disconnected, or Degraded) for customers with a Runtime license, providing at-a-glance coverage and connectivity insights for deployed sensors.
- Compliance Rule Mapping: Introduced a unified compliance mapping experience in the Insights Library with support for custom rule management on compliance packs.
- Unified compliance mapping action: The separate Edit Metadata and Add to Custom Pack actions have been replaced by a single Map to Compliance Pack action, available as both a row action and a bulk action in the Insights Library. The new action handles pack membership and compliance rule mapping in one step.
- Compliance rule mapping: When mapping an Insight to a compliance pack, you can now select one or more compliance rules from a cascading dropdown. If no rules are selected, only pack membership is added (equivalent to the previous Add to Custom Pack behavior).
- Custom compliance rules on packs: Custom packs now support user-defined compliance rules (for example,
Custom Control 1.3orInternal Policy 2.1). Rules can be added, renamed, and deleted from the new Compliance Rules tab on the pack detail page. Renaming a rule preserves all existing Insight mappings. - Rule inheritance from base packs: Custom packs can inherit rules from base packs. Inherited rules are read-only and cannot be modified on the child pack.
- Compliance Rules tab: The pack detail page now includes a Compliance Rules tab showing all rules associated with the pack, including user-defined rules and rules inherited from base packs. Rules can be filtered by source (Custom or Inherited).
- New API endpoints: Available for managing compliance rules and mappings programmatically.
GET /pack/{pack_id}/insight-rule-mappings: Returns Insight-to-rule mappings for a specific packGET /packs-with-rules: Returns all packs with their available rulesPOST /map-to-compliance-rule: Maps Insights to compliance rules within a packGET /pack/{pack_id}/rules: Lists all rules on a pack with Insight countsPOST /pack/{pack_id}/rules/create: Creates a custom rule on a packPOST /pack/{pack_id}/rules/delete: Deletes a custom rule from a packPOST /pack/{pack_id}/rules/rename: Renames a custom rule, preserving all existing mappings
New Compliance Packs
- Added the CIS Microsoft Azure Storage Services Benchmark v1.0.0 compliance pack.
New Insights
- Serverless Function Configured With Deprecated Runtime: Identifies AWS Lambda functions configured with a deprecated runtime. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.11, CIS Controls v8.1.2 safeguard 7.4, NIST SP 800-53 Rev. 5, and CMMC Level 1 and CMMC Level 2.
- Serverless Function With Admin Role: Identifies AWS Lambda functions configured with full administrative privileges. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.9, NIST SP 800-53, NIST CSF v2.0, and CMMC.
- Serverless Function With Public Access Policy: Identifies AWS Lambda functions that are publicly accessible via a resource-based policy. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 12.6.
- Web App With Load Balancer Using HTTP: Identifies Web Apps whose load balancer has a listener that uses HTTP.
New Query Filters
- Serverless Function With Admin Role: Filters AWS Lambda functions whose execution role grants full administrative privileges.
- Load Balancer Listener Frontend Protocols: Filters load balancers based on the frontend protocols their listeners use.
- Load Balancer Listener Instance Protocols: Filters load balancers based on the instance protocols their listeners use.
- Web App Load Balancer HTTP Configuration: Filters Web Apps whose load balancer has a listener that uses HTTP.
Updated Insights
- Updated Instance Containing Sensitive Information In User Data (AWS) to include CIS-recommended remediation steps. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.13.
- Updated Instance not Managed by AWS Systems Manager to align with CIS v8 documentation, including updated remediation guidance. Added Feature Disabled and IAM tags for improved discoverability. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.9.
- Updated Instance Allows Use of Vulnerable IMDSv1 Protocol (AWS) to align with current style guidelines. Added compliance mappings for CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, CMMC Level 1, and CMMC Level 2. Maps to CIS AWS Compute Services Benchmark v1.1.0 control 2.8.
Updated Query Filters
- Renamed Load Balancer With HTTP Listener Not Redirecting To HTTPS to Load Balancer Comprehensive HTTP to HTTPS Redirection. Added a new All HTTP Listeners Redirect to HTTPS configuration option to identify load balancers where all HTTP listeners redirect requests to HTTPS.
Improved
- Added a search input field to the Bot matched resources modal, allowing users to quickly locate a specific resource by name when a bot matches against a large number of resources.
Deprecations
- Deprecated Query Filter: “Snapshot Accessible To Public”, renamed to “Snapshot Accessible To Public (Deprecated)”. Its functionality is now covered by the following two Query Filters:
- “Snapshot Public Access”
- “Database Snapshot Public Access” (new)
- Deprecated Insight: “Snapshot Available to the Public” (Targeted deprecation in version 26.7, targeted removal in version 27.1). Its functionality can be replaced by the following two Insights:
- “Snapshot Is Accessible to the Public”
- “Database Snapshot Is Accessible to the Public” (new)
- Compliance pack mappings have been updated to reference the replacement Insights.
Fixed
- Fixed two issues affecting the IAM Principal Explorer. The Policy Stack link in the Resource Details > Permissions panel was navigating to an incorrect URL, resulting in an infinite loading state. Additionally, certain cloud roles caused the Principal Explorer to fail to render, displaying a
Cannot destructure property 'id'error. Both navigation and rendering now work correctly. - Fixed a UI rendering issue where the navigation menu (accessed via the dot-grid icon in the top left) appeared behind the main frame due to a z-index conflict with the side navigation drawer.
- Fixed an issue where the “Section” column was missing from Compliance Scorecard email subscription reports. Reports generated after June 1st were omitting this column; the field now populates correctly across all report exports.
- Fixed an issue where Azure Function App Python runtime detection was using the legacy
pythonVersionattribute instead of the currentlinuxFxVersionattribute used by Linux-based function apps, resulting in missing runtime version data for affected resources. - Fixed an issue where the Database Instances Without Automatic Backups insight was incorrectly flagging GCP read replica instances as non-compliant. Read replicas inherit backup configuration from their primary instance and are no longer evaluated against this insight.
- Fixed Microsoft Teams bot notification messages not rendering at full width by correcting an Adaptive Card property key casing issue.
Version 26.7.7
Software release date: July 9, 2026 | Release notes published: July 9, 2026
Improved
- Added background job
OrphanedCredentialCleanupthat removes orphaned cloud credentials daily or on-demand. These orphaned credentials are unused by harvesting or other portions of the product.
New Insights
- Ensure EC2 Auto Scaling Groups Propagate Tags to Launched Instances (Insight ID 2582) - Detects AWS Auto Scaling Groups where one or more tags are not configured to propagate to the EC2 instances they launch. This aligns with CIS AWS Compute Services Benchmark control 2.14.
- Supported Clouds: AWS, AWS China, AWS GovCloud.
- Compliance Pack Mappings: CIS Controls v8.1.2 (1.1), NIST 800-53 Rev 5 (CM-8, CM-8(1), PM-5), NIST 800-171 (3.4.1, 3.4.9, 3.12.4), NIST CSF 2.0 (ID.AM-01, ID.AM-07), CMMC Level 2 (CM.L2-3.4.1, CA.L2-3.12.4).
- After re-harvesting, Auto Scaling Groups will show tag propagation compliance status. Groups with no tags are considered compliant. Groups not yet re-harvested will show as “unknown” and will not trigger findings.
- Volume Not Marked for Deletion on Instance Termination (Insight ID 2591) - Identifies EBS Volumes attached to EC2 Instances that are not configured for automatic deletion upon Instance Termination, helping reduce orphaned resources and potential data exposure. Aligned with CIS AWS Compute Services Benchmark Control 2.12.
- Compliance Pack Mappings: CIS Controls v8.1.2, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, NIST CSF v2.0, and CMMC Level 2.
- Instance Using Default Security Group - Identifies AWS EC2 Instances that are associated with a default security group rather than a specified custom security group.
- Cloud Account Organization Without Tag Policy Enabled - Identifies management Cloud Accounts whose AWS Organization does not have Tag Policies enabled.
New Query Filters
- Autoscaling Group Not Propagating Tags at Launch - Identifies Auto Scaling Groups where tags are not configured to propagate to launched instances.
- Supported Clouds: AWS, AWS China, AWS GovCloud.
- Cloud Account Organization Tag Policy Status - Identifies management Cloud Accounts based on Tag Policy enablement status at the Organization root.
New Compliance Pack
- Added CIS Red Hat OpenShift Container Platform Benchmark v1.9.0 compliance pack.
Fixed
- Fixed Cache Instance Auth Token Disabled Query Filter false positive. The filter now correctly inherits
auth_tokenconfiguration. - Fixed Resource Associated With Public Subnet Query Filter to correctly detect ElastiCache public subnet associations in CloudFormation Template (CFT) scans.
- Fixed an error that could cause IaC scan listing to fail with a database session error.
- Fixed an issue where resources with exceptions were not showing on the misconfiguration UI and export.
- Resolved intermittent Azure snapshot harvesting failures. Fixed an issue where the Azure snapshot harvester could intermittently fail with a
NotImplementedError, preventing snapshot data from being collected during affected harvest runs.- The snapshot harvesting method is now defined directly on the Azure backend class, consistent with how all other cloud providers (AWS, GCP, AliCloud, Oracle) are implemented.
- No changes to harvested data or behavior — runs that previously succeeded continue to work identically.
Mimics Infrastructure as Code (IaC) Scanning Tool
No updates released at this time.
SIEM (InsightIDR)
Improved:
- Updated SentinelOne Third-Party Alert library to use inherited priority functionality.
Vulnerability Management (InsightVM)
Fixed
- No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in Scan Engine content version 1.1.3935.
Version 8.52.0
Software release date: July 13, 2026 | Release notes published: July 13, 2026
Improved:
- Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
- Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
- Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.
Fixed:
- Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
- Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
- Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
- Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.
Version 8.51.0
Software release date: July 7, 2026 | Release notes published: July 6, 2026
Improved:
- Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
- Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
- Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
- Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
- Added built-in policy support for:
- DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
- DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
- Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.
Fixed:
- Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
- Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
- Resolved an issue affecting Extensible Ingress when using a console proxy. Exposure Analytics traffic now correctly routes through the configured proxy, including authenticated proxies. A Security Console restart is required when using an authenticated proxy.
Nexpose
Fixed
- No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in Scan Engine content version 1.1.3935.
Nexpose Version 8.52.0
Software release date: July 13, 2026 | Release notes published: July 13, 2026
Improved:
- Improved Splunk Enterprise fingerprinting on Unix/Linux. Added a dedicated fingerprinter that detects Splunk Enterprise by querying the product directly for its version, replacing the previous OS package-based detection.This improves coverage for Splunk installations deployed outside the system package manager (e.g., tarball installs under /opt/splunk), resulting in more accurate software inventory and vulnerability assessment on affected hosts.
- Added fingerprinting support for AI tools, MCP servers, and AI development skills, providing greater visibility into AI technologies deployed across your environment to help identify both authorized and unauthorized usage.
- Added fingerprinting support for Microsoft Intune-managed applications. The scan engine can now detect and inventory software deployed and managed through Microsoft Intune (Microsoft Endpoint Manager), including Win32 apps, MSI line-of-business apps, and Microsoft Store for Business apps. This enhancement enables accurate software fingerprinting on Windows 10/11 endpoints enrolled in Intune, with proper version reporting that matches the Intune console. Duplicate software entries are reconciled when both a local installer and an Intune-managed installer are detected for the same application. Vulnerability assessments are automatically applied to discovered Intune-managed software where existing content coverage is available.
Fixed:
- Resolved an issue where the scan engine incorrectly reported a Diffie-Hellman key size of 0 for TLS 1.3 services.
- Fixed an issue where wildcard CVE searches in the General Search vulnerability tab could return incomplete or incorrect results. Wildcard prefix matching now behaves as expected.
- Addressed an issue preventing reverse-paired Scan Engines from reconnecting automatically after a Security Console restart. Previously paired engines now reconnect as expected.
- Fixed an issue that could cause PostgreSQL 15 major version migrations to fail during upgrade. Database migrations now complete successfully.
Nexpose Version 8.51.0
Software release date: July 7, 2026 | Release notes published: July 6, 2026
Improved:
- Enhanced Oracle Access Management fingerprinting to improve patch version identification and reporting accuracy.
- Improved scan logging for custom service names configuration issues, providing clearer messages when files are missing or cannot be parsed to simplify troubleshooting.
- Strengthened the overall security posture of the Security Console by upgrading the bundled Axios library to the latest supported minor version.
- Improved the performance and responsiveness of the Asset Search API, particularly for larger Security Console deployments.
- Added built-in policy support for:
- DISA STIG Microsoft SQL Server Database 2022 Benchmark V1R3
- DISA STIG Microsoft SQL Server Instance 2022 Benchmark V1R4
- Operating System Support: Added support for Microsoft Windows Server 2025 on the Vulnerability Management (InsightVM) Console, Nexpose Console, and Scan Engines.
Fixed:
- Resolved an issue where the GET Scan Engine Sites API returned an incomplete value for scanTemplateName. The endpoint now returns the expected scan template name.
- Fixed an issue where CSV vulnerability reports did not include tabular solution content, such as Windows Registry settings and configuration values. This information is now exported correctly.
Digital Risk Protection (Threat Command)
Software release date: [June 19, 2026] | Release notes published: [July 6, 2026]
New:
- You can now control whether infostealer alerts include external user matches — credentials associated with a customer-owned domain but without an organizational email address. The toggle is located under Configurations > Customization in Digital Risk Protection (Threat Command), or under Intelligence > DRP Configurations > Customization in the Command Platform. External user alerting is on by default, preserving existing behavior. When turned off, monitoring stops for external email matches while internal organizational email monitoring continues. This setting applies to future alerts only and has no effect on existing or previously resolved alerts.
Rapid7 Agent (Insight Agent)
Version 4.1.1 (Unchanged from previous release version)
Fixed:
- No longer executes files discovered on a target asset without verifying ownership during authenticated assessment, preventing a local privilege escalation (CVE-2026-14172). This fix is included in content component version 0.0.245.0.
Resolved an issue in a third-party Go library that prevented some Rapid7 Agent (Insight Agent) capabilities from working as intended on devices with Apple M5 Pro and M5 Max chipsets. The following capabilities are now restored on affected devices:
- Endpoint Protection and Ransomware Prevention
- Agent-based Policy
- Hosted Velociraptor
- On-demand vulnerability scans
If Command Platform (Insight Platform)-managed agent updates are enabled, the Rapid7 Agent (Insight Agent) will automatically update the Endpoint Broker, Agent Core, and Hosted Velociraptor components. For more information, see Data collected by the Rapid7 Agent (Insight Agent) and Command Platform (Insight Platform)-managed agent updates .
Next-Generation Antivirus
No updates released at this time.
Ransomware Prevention
No updates released at this time.
Velociraptor
Version 0.74.4.27
Software release date: [July 8, 2026] | Release notes published: [July 8, 2026]
Fixed:
Resolved an issue in a third-party Go library that prevented the Rapid7 Velociraptor client from working as intended on devices with Apple M5 Pro and M5 Max chipsets. For more information, see the Rapid7 Agent Release Notes.
Automation (InsightConnect)
No updates released at this time.
Rapid7 Network Sensor (Insight Network Sensor)
Version 2.1.0.1
Software release date: July 7, 2026 | Release notes published: July 16, 2026
Improved:
- Suricata received a major version upgrade from 7.0.15 to 8.0.5.
- Support for the HL7 protocol, common in healthcare environments, has been overhauled to improve detection and reduce false positives.
- Overhauled Zoom protocol support to improve detection accuracy, reduce false positives, and more accurately identify client and server roles.
- Enhanced telemetry for ambiguous network traffic that matches multiple protocols. These improvements provide better visibility into protocol identification and support future enhancements to protocol recognition.
Fixed:
- Fixed issues in SMTP direction finding to improve identification of SMTP servers.
- Fixed false-negative issues affecting NNTP, FTP, SMTP, and POP3 protocol detection.
- Fixed issues in Kerberos (krb5) protocol detection to improve Kerberos traffic detection.
- Fixed an issue in the NetBIOS datagram protocol decoder to improve NetBIOS traffic detection.
New Protocols:
- VNC: The sensor now detects the Virtual Network Computing (VNC) protocol, which is used for remote desktop access and control. This is an important protocol to detect as there is a potential security risk if there are unauthorized VNC servers running on the network, especially on unusual ports.
- WCF (Windows Communication Foundation): The sensor now detects the WCF protocol, which is used by Microsoft applications for inter-process communication.
- Meraki Cloud Protocol: The sensor now detects the Meraki Cloud Protocol, which is used by Cisco Meraki devices for cloud management and communication. This decoder was the result of AI-assisted protocol reverse-engineering.
- Centrak Real-Time Location System (RTLS): The sensor now detects the Centrak RTLS protocol, which is used for tracking and managing assets in healthcare and other industries. This decoder was the result of AI-assisted protocol reverse-engineering.
- JetDirect (PJL): The sensor now detects the JetDirect Printer Job Language (PJL) protocol, which is used by HP printers for job control and status reporting.
Version 2.0.0.2
Software released: June 4, 2026 | Release notes published: July 14, 2026
Improved:
-
Removed DPDK as a dependency and replaced it with custom thread-management and memory allocations, resulting in a 7.6% packet capture performance improvement.
-
Raised thread limit from 16 to 32, resulting in better performance on 100 Gbps sensors with sufficient hardware.
-
This release includes improvements to event throughput.
Fixed:
- Fixed a bug where multicast flows would sometimes be assigned the wrong direction.
- Fixed protocol detection accuracy for STUN and mDNS.
New Protocols:
- WUDO: The sensor now detects the Windows Update Delivery Optimization (WUDO) protocol, which is used by Windows endpoints to share update content peer-to-peer across a local network.
- Cohesity RPC protocol: The sensor now detects the Cohesity Remote Procedure Call (RPC) protocol, used by the Cohesity Data Protection and Security Platform.
- Aerohive Mobility Routing protocol: The sensor now detects the Aerohive Mobility Routing protocol, used by Aerohive wireless infrastructure for access point coordination.